Changelog for
pam_ssh_agent_auth-0.9.2-26.24.fc14.2.x86_64.rpm :
Wed Nov 24 13:00:00 2010 Jan F. Chadima
- 5.5p1-24 + 0.9.2-26
- reapair clientloop crash (#627332)
Fri Nov 5 13:00:00 2010 Jan F. Chadima - 5.5p1-23 + 0.9.2-26
- update x11 patch (#648896)
Wed Oct 20 14:00:00 2010 Jan F. Chadima - 5.5p1-22 + 0.9.2-26
- update gsskex patch (#645389)
Tue Oct 5 14:00:00 2010 jkeating - 5.5p1-21.2
- Rebuilt for gcc bug 634757
Wed Sep 15 14:00:00 2010 Jan F. Chadima - 5.5p1-21 + 0.9.2-26
- Add the GSSAPI kuserok switch to the kuserok patch
Mon Sep 13 14:00:00 2010 Jan F. Chadima - 5.5p1-20 + 0.9.2-26
- Tweaking selabel patch to work properly without selinux rules loaded. (#632914)
- enabling authorized keys command patch
Fri Sep 3 14:00:00 2010 Jan F. Chadima - 5.5p1-19 + 0.9.2-26
- Added -z relro -z now to LDFLAGS
Wed Jul 7 14:00:00 2010 Jan F. Chadima - 5.5p1-18 + 0.9.2-26
- merged with newer bugzilla\'s version of authorized keys command patch
Wed Jun 30 14:00:00 2010 Jan F. Chadima - 5.5p1-17 + 0.9.2-26
- improved the x11 patch according to upstream (#598671)
Fri Jun 25 14:00:00 2010 Jan F. Chadima - 5.5p1-16 + 0.9.2-26
- improved the x11 patch (#598671)
Thu Jun 24 14:00:00 2010 Jan F. Chadima - 5.5p1-15 + 0.9.2-26
- changed _PATH_UNIX_X to unexistent file name (#598671)
Wed Jun 23 14:00:00 2010 Jan F. Chadima - 5.5p1-14 + 0.9.2-26
- sftp works in deviceless chroot again (broken from 5.5p1-3)
Tue Jun 8 14:00:00 2010 Jan F. Chadima - 5.5p1-13 + 0.9.2-26
- add option to switch out krb5_kuserok
Fri May 21 14:00:00 2010 Jan F. Chadima - 5.5p1-12 + 0.9.2-26
- synchronize uid and gid for the user sshd
Thu May 20 14:00:00 2010 Jan F. Chadima - 5.5p1-11 + 0.9.2-26
- Typo in ssh-ldap.conf(5) and ssh-ladap-helper(8)
Fri May 14 14:00:00 2010 Jan F. Chadima - 5.5p1-10 + 0.9.2-26
- Repair the reference in man ssh-ldap-helper(8)
- Repair the PubkeyAgent section in sshd_config(5)
- Provide example ldap.conf
Thu May 13 14:00:00 2010 Jan F. Chadima - 5.5p1-9 + 0.9.2-26
- Make the Ldap configuration widely compatible
- create the aditional docs for LDAP support.
Thu May 6 14:00:00 2010 Jan F. Chadima - 5.5p1-8 + 0.9.2-26
- Make LDAP config elements TLS_CACERT and TLS_REQCERT compatiple with pam_ldap (#589360)
Thu May 6 14:00:00 2010 Jan F. Chadima - 5.5p1-7 + 0.9.2-26
- Make LDAP config element tls_checkpeer compatiple with nss_ldap (#589360)
Tue May 4 14:00:00 2010 Jan F. Chadima - 5.5p1-6 + 0.9.2-26
- Comment spec.file
- Sync patches from upstream
Mon May 3 14:00:00 2010 Jan F. Chadima - 5.5p1-5 + 0.9.2-26
- Create separate ldap package
- Tweak the ldap patch
- Rename stderr patch properly
Thu Apr 29 14:00:00 2010 Jan F. Chadima - 5.5p1-4 + 0.9.2-26
- Added LDAP support
Mon Apr 26 14:00:00 2010 Jan F. Chadima - 5.5p1-3 + 0.9.2-26
- Ignore .bashrc output to stderr in the subsystems
Tue Apr 20 14:00:00 2010 Jan F. Chadima - 5.5p1-2 + 0.9.2-26
- Drop dependency on man
Fri Apr 16 14:00:00 2010 Jan F. Chadima - 5.5p1-1 + 0.9.2-26
- Update to 5.5p1
Fri Mar 12 13:00:00 2010 Jan F. Chadima - 5.4p1-3 + 0.9.2-25
- repair configure script of pam_ssh_agent
- repair error mesage in ssh-keygen
Fri Mar 12 13:00:00 2010 Jan F. Chadima - 5.4p1-2
- source krb5-devel profile script only if exists
Tue Mar 9 13:00:00 2010 Jan F. Chadima - 5.4p1-1
- Update to 5.4p1
- discontinued support for nss-keys
- discontinued support for scard
Wed Mar 3 13:00:00 2010 Jan F. Chadima - 5.4p1-0.snap20100302.1
- Prepare update to 5.4p1
Mon Feb 15 13:00:00 2010 Jan F. Chadima - 5.3p1-22
- ImplicitDSOLinking (#564824)
Fri Jan 29 13:00:00 2010 Jan F. Chadima - 5.3p1-21
- Allow to use hardware crypto if awailable (#559555)
Mon Jan 25 13:00:00 2010 Jan F. Chadima - 5.3p1-20
- optimized FD_CLOEXEC on accept socket (#541809)
Mon Jan 25 13:00:00 2010 Tomas Mraz - 5.3p1-19
- updated pam_ssh_agent_auth to new version from upstream (just
a licence change)
Thu Jan 21 13:00:00 2010 Jan F. Chadima - 5.3p1-18
- optimized RAND_cleanup patch (#557166)
Wed Jan 20 13:00:00 2010 Jan F. Chadima - 5.3p1-17
- add RAND_cleanup at the exit of each program using RAND (#557166)
Tue Jan 19 13:00:00 2010 Jan F. Chadima - 5.3p1-16
- set FD_CLOEXEC on accepted socket (#541809)
Fri Jan 8 13:00:00 2010 Jan F. Chadima - 5.3p1-15
- replaced define by global in macros
Tue Jan 5 13:00:00 2010 Jan F. Chadima - 5.3p1-14
- Update the pka patch
Mon Dec 21 13:00:00 2009 Jan F. Chadima - 5.3p1-13
- Update the audit patch
Fri Dec 4 13:00:00 2009 Jan F. Chadima - 5.3p1-12
- Add possibility to autocreate only RSA key into initscript (#533339)
Fri Nov 27 13:00:00 2009 Jan F. Chadima - 5.3p1-11
- Prepare NSS key patch for future SEC_ERROR_LOCKED_PASSWORD (#537411)
Tue Nov 24 13:00:00 2009 Jan F. Chadima - 5.3p1-10
- Update NSS key patch (#537411, #356451)
Fri Nov 20 13:00:00 2009 Jan F. Chadima - 5.3p1-9
- Add gssapi key exchange patch (#455351)
Fri Nov 20 13:00:00 2009 Jan F. Chadima - 5.3p1-8
- Add public key agent patch (#455350)
Mon Nov 2 13:00:00 2009 Jan F. Chadima - 5.3p1-7
- Repair canohost patch to allow gssapi to work when host is acessed via pipe proxy (#531849)
Thu Oct 29 13:00:00 2009 Jan F. Chadima - 5.3p1-6
- Modify the init script to prevent it to hang during generating the keys (#515145)
Tue Oct 27 13:00:00 2009 Jan F. Chadima - 5.3p1-5
- Add README.nss
Mon Oct 19 14:00:00 2009 Tomas Mraz - 5.3p1-4
- Add pam_ssh_agent_auth module to a subpackage.
Fri Oct 16 14:00:00 2009 Jan F. Chadima - 5.3p1-3
- Reenable audit.
Fri Oct 2 14:00:00 2009 Jan F. Chadima - 5.3p1-2
- Upgrade to new wersion 5.3p1
Tue Sep 29 14:00:00 2009 Jan F. Chadima - 5.2p1-29
- Resolve locking in ssh-add (#491312)
Thu Sep 24 14:00:00 2009 Jan F. Chadima - 5.2p1-28
- Repair initscript to be acord to guidelines (#521860)
- Add bugzilla# to application of edns and xmodifiers patch
Wed Sep 16 14:00:00 2009 Jan F. Chadima - 5.2p1-26
- Changed pam stack to password-auth
Fri Sep 11 14:00:00 2009 Jan F. Chadima - 5.2p1-25
- Dropped homechroot patch
Mon Sep 7 14:00:00 2009 Jan F. Chadima - 5.2p1-24
- Add check for nosuid, nodev in homechroot
Tue Sep 1 14:00:00 2009 Jan F. Chadima - 5.2p1-23
- add correct patch for ip-opts
Tue Sep 1 14:00:00 2009 Jan F. Chadima - 5.2p1-22
- replace ip-opts patch by an upstream candidate version
Mon Aug 31 14:00:00 2009 Jan F. Chadima - 5.2p1-21
- rearange selinux patch to be acceptable for upstream
- replace seftp patch by an upstream version
Fri Aug 28 14:00:00 2009 Jan F. Chadima - 5.2p1-20
- merged xmodifiers to redhat patch
- merged gssapi-role to selinux patch
- merged cve-2007_3102 to audit patch
- sesftp patch only with WITH_SELINUX flag
- rearange sesftp patch according to upstream request
Wed Aug 26 14:00:00 2009 Jan F. Chadima - 5.2p1-19
- minor change in sesftp patch
Fri Aug 21 14:00:00 2009 Tomas Mraz - 5.2p1-18
- rebuilt with new openssl
Thu Jul 30 14:00:00 2009 Jan F. Chadima - 5.2p1-17
- Added dnssec support. (#205842)
Sat Jul 25 14:00:00 2009 Fedora Release Engineering - 5.2p1-16
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
Fri Jul 24 14:00:00 2009 Jan F. Chadima - 5.2p1-15
- only INTERNAL_SFTP can be home-chrooted
- save _u and _r parts of context changing to sftpd_t
Fri Jul 17 14:00:00 2009 Jan F. Chadima - 5.2p1-14
- changed internal-sftp context to sftpd_t
Fri Jul 3 14:00:00 2009 Jan F. Chadima - 5.2p1-13
- changed home length path patch to upstream version
Tue Jun 30 14:00:00 2009 Jan F. Chadima - 5.2p1-12
- create \'~/.ssh/known_hosts\' within proper context
Mon Jun 29 14:00:00 2009 Jan F. Chadima - 5.2p1-11
- length of home path in ssh now limited by PATH_MAX
- correct timezone with daylight processing
Sat Jun 27 14:00:00 2009 Jan F. Chadima - 5.2p1-10
- final version chroot %h (sftp only)
Tue Jun 23 14:00:00 2009 Jan F. Chadima - 5.2p1-9
- repair broken ls in chroot %h
Fri Jun 12 14:00:00 2009 Jan F. Chadima - 5.2p1-8
- add XMODIFIERS to exported environment (#495690)
Fri May 15 14:00:00 2009 Tomas Mraz - 5.2p1-6
- allow only protocol 2 in the FIPS mode
Thu Apr 30 14:00:00 2009 Tomas Mraz - 5.2p1-5
- do integrity verification only on binaries which are part
of the OpenSSH FIPS modules
Mon Apr 20 14:00:00 2009 Tomas Mraz - 5.2p1-4
- log if FIPS mode is initialized
- make aes-ctr cipher modes work in the FIPS mode
Fri Apr 3 14:00:00 2009 Jan F. Chadima - 5.2p1-3
- fix logging after chroot
- enable non root users to use chroot %h in internal-sftp
Fri Mar 13 13:00:00 2009 Tomas Mraz - 5.2p1-2
- add AES-CTR ciphers to the FIPS mode proposal
Mon Mar 9 13:00:00 2009 Jan F. Chadima - 5.2p1-1
- upgrade to new upstream release
Thu Feb 26 13:00:00 2009 Fedora Release Engineering - 5.1p1-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
Thu Feb 12 13:00:00 2009 Tomas Mraz - 5.1p1-7
- drop obsolete triggers
- add testing FIPS mode support
- LSBize the initscript (#247014)
Fri Jan 30 13:00:00 2009 Tomas Mraz - 5.1p1-6
- enable use of ssl engines (#481100)
Thu Jan 15 13:00:00 2009 Tomas Mraz - 5.1p1-5
- remove obsolete --with-rsh (#478298)
- add pam_sepermit to allow blocking confined users in permissive mode
(#471746)
- move system-auth after pam_selinux in the session stack
Thu Dec 11 13:00:00 2008 Tomas Mraz - 5.1p1-4
- set FD_CLOEXEC on channel sockets (#475866)
- adjust summary
- adjust nss-keys patch so it is applicable without selinux patches (#470859)
Fri Oct 17 14:00:00 2008 Tomas Mraz - 5.1p1-3
- fix compatibility with some servers (#466818)
Thu Jul 31 14:00:00 2008 Tomas Mraz - 5.1p1-2
- fixed zero length banner problem (#457326)
Wed Jul 23 14:00:00 2008 Tomas Mraz - 5.1p1-1
- upgrade to new upstream release
- fixed a problem with public key authentication and explicitely
specified SELinux role
Wed May 21 14:00:00 2008 Tomas Mraz - 5.0p1-3
- pass the connection socket to ssh-keysign (#447680)
Mon May 19 14:00:00 2008 Tomas Mraz - 5.0p1-2
- add LANGUAGE to accepted/sent environment variables (#443231)
- use pam_selinux to obtain the user context instead of doing it itself
- unbreak server keep alive settings (patch from upstream)
- small addition to scp manpage
Mon Apr 7 14:00:00 2008 Tomas Mraz - 5.0p1-1
- upgrade to new upstream (#441066)
- prevent initscript from killing itself on halt with upstart (#438449)
- initscript status should show that the daemon is running
only when the main daemon is still alive (#430882)
Thu Mar 6 13:00:00 2008 Tomas Mraz - 4.7p1-10
- fix race on control master and cleanup stale control socket (#436311)
patches by David Woodhouse
Fri Feb 29 13:00:00 2008 Tomas Mraz - 4.7p1-9
- set FD_CLOEXEC on client socket
- apply real fix for window size problem (#286181) from upstream
- apply fix for the spurious failed bind from upstream
- apply open handle leak in sftp fix from upstream
Tue Feb 12 13:00:00 2008 Dennis Gilmore - 4.7p1-8
- we build for sparcv9 now and it needs -fPIE
Thu Jan 3 13:00:00 2008 Tomas Mraz - 4.7p1-7
- fix gssapi auth with explicit selinux role requested (#427303) - patch
by Nalin Dahyabhai
Tue Dec 4 13:00:00 2007 Tomas Mraz - 4.7p1-6
- explicitly source krb5-devel profile script
Tue Dec 4 13:00:00 2007 Release Engineering - 4.7p1-5
- Rebuild for openssl bump
Tue Nov 20 13:00:00 2007 Tomas Mraz - 4.7p1-4
- do not copy /etc/localtime into the chroot as it is not
necessary anymore (#193184)
- call setkeycreatecon when selinux context is established
- test for NULL privk when freeing key (#391871) - patch by
Pierre Ossman
Mon Sep 17 14:00:00 2007 Tomas Mraz - 4.7p1-2
- revert default window size adjustments (#286181)
Thu Sep 6 14:00:00 2007 Tomas Mraz - 4.7p1-1
- upgrade to latest upstream
- use libedit in sftp (#203009)
- fixed audit log injection problem (CVE-2007-3102)
Thu Aug 9 14:00:00 2007 Tomas Mraz - 4.5p1-8
- fix sftp client problems on write error (#247802)
- allow disabling autocreation of server keys (#235466)
Wed Jun 20 14:00:00 2007 Tomas Mraz - 4.5p1-7
- experimental NSS keys support
- correctly setup context when empty level requested (#234951)
Tue Mar 20 13:00:00 2007 Tomas Mraz - 4.5p1-6
- mls level check must be done with default role same as requested
Mon Mar 19 13:00:00 2007 Tomas Mraz - 4.5p1-5
- make profile.d/gnome-ssh-askpass.
* regular files (#226218)
Tue Feb 27 13:00:00 2007 Tomas Mraz - 4.5p1-4
- reject connection if requested mls range is not obtained (#229278)
Thu Feb 22 13:00:00 2007 Tomas Mraz - 4.5p1-3
- improve Buildroot
- remove duplicate /etc/ssh from files
Tue Jan 16 13:00:00 2007 Tomas Mraz - 4.5p1-2
- support mls on labeled networks (#220487)
- support mls level selection on unlabeled networks
- allow / in usernames in scp (only beginning /, ./, and ../ is special)
Thu Dec 21 13:00:00 2006 Tomas Mraz - 4.5p1-1
- update to 4.5p1 (#212606)
Thu Nov 30 13:00:00 2006 Tomas Mraz - 4.3p2-14
- fix gssapi with DNS loadbalanced clusters (#216857)
Tue Nov 28 13:00:00 2006 Tomas Mraz - 4.3p2-13
- improved pam_session patch so it doesn\'t regress, the patch is necessary
for the pam_session_close to be called correctly as uid 0
Fri Nov 10 13:00:00 2006 Tomas Mraz - 4.3p2-12
- CVE-2006-5794 - properly detect failed key verify in monitor (#214641)
Thu Nov 2 13:00:00 2006 Tomas Mraz - 4.3p2-11
- merge sshd initscript patches
- kill all ssh sessions when stop is called in halt or reboot runlevel
- remove -TERM option from killproc so we don\'t race on sshd restart
Mon Oct 2 14:00:00 2006 Tomas Mraz - 4.3p2-10
- improve gssapi-no-spnego patch (#208102)
- CVE-2006-4924 - prevent DoS on deattack detector (#207957)
- CVE-2006-5051 - don\'t call cleanups from signal handler (#208459)
Wed Aug 23 14:00:00 2006 Tomas Mraz - 4.3p2-9
- don\'t report duplicate syslog messages, use correct local time (#189158)
- don\'t allow spnego as gssapi mechanism (from upstream)
- fixed memleaks found by Coverity (from upstream)
- allow ip options except source routing (#202856) (patch by HP)
Tue Aug 8 14:00:00 2006 Tomas Mraz - 4.3p2-8
- drop the pam-session patch from the previous build (#201341)
- don\'t set IPV6_V6ONLY sock opt when listening on wildcard addr (#201594)
Thu Jul 20 14:00:00 2006 Tomas Mraz - 4.3p2-7
- dropped old ssh obsoletes
- call the pam_session_open/close from the monitor when privsep is
enabled so it is always called as root (patch by Darren Tucker)
Mon Jul 17 14:00:00 2006 Tomas Mraz - 4.3p2-6
- improve selinux patch (by Jan Kiszka)
- upstream patch for buffer append space error (#191940)
- fixed typo in configure.ac (#198986)
- added pam_keyinit to pam configuration (#198628)
- improved error message when askpass dialog cannot grab
keyboard input (#198332)
- buildrequires xauth instead of xorg-x11-xauth
- fixed a few rpmlint warnings
Wed Jul 12 14:00:00 2006 Jesse Keating - 4.3p2-5.1
- rebuild
Fri Apr 14 14:00:00 2006 Tomas Mraz - 4.3p2-5
- don\'t request pseudoterminal allocation if stdin is not tty (#188983)
Thu Mar 2 13:00:00 2006 Tomas Mraz - 4.3p2-4
- allow access if audit is not compiled in kernel (#183243)
Fri Feb 24 13:00:00 2006 Tomas Mraz - 4.3p2-3
- enable the subprocess in chroot to send messages to system log
- sshd should prevent login if audit call fails
Tue Feb 21 13:00:00 2006 Tomas Mraz - 4.3p2-2
- print error from scp if not remote (patch by Bjorn Augustsson #178923)
Mon Feb 13 13:00:00 2006 Tomas Mraz - 4.3p2-1
- new version
Fri Feb 10 13:00:00 2006 Jesse Keating - 4.3p1-2.1
- bump again for double-long bug on ppc(64)
Mon Feb 6 13:00:00 2006 Tomas Mraz - 4.3p1-2
- fixed another place where syslog was called in signal handler
- pass locale environment variables to server, accept them there (#179851)
Wed Feb 1 13:00:00 2006 Tomas Mraz - 4.3p1-1
- new version, dropped obsolete patches
Tue Dec 20 13:00:00 2005 Tomas Mraz - 4.2p1-10
- hopefully make the askpass dialog less confusing (#174765)
Fri Dec 9 13:00:00 2005 Jesse Keating
- rebuilt
Tue Nov 22 13:00:00 2005 Tomas Mraz - 4.2p1-9
- drop x11-ssh-askpass from the package
- drop old build_6x ifs from spec file
- improve gnome-ssh-askpass so it doesn\'t reveal number of passphrase
characters to person looking at the display
- less hackish fix for the __USE_GNU problem
Fri Nov 18 13:00:00 2005 Nalin Dahyabhai - 4.2p1-8
- work around missing gccmakedep by wrapping makedepend in a local script
- remove now-obsolete build dependency on \"xauth\"
Thu Nov 17 13:00:00 2005 Warren Togami - 4.2p1-7
- xorg-x11-devel -> libXt-devel
- rebuild for new xauth location so X forwarding works
- buildreq audit-libs-devel
- buildreq automake for aclocal
- buildreq imake for xmkmf
- -D_GNU_SOURCE in flags in order to get it to build
Ugly hack to workaround openssh defining __USE_GNU which is
not allowed and causes problems according to Ulrich Drepper
fix this the correct way after FC5test1
Wed Nov 9 13:00:00 2005 Jeremy Katz - 4.2p1-6
- rebuild against new openssl
Fri Oct 28 14:00:00 2005 Tomas Mraz 4.2p1-5
- put back the possibility to skip SELinux patch
- add patch for user login auditing by Steve Grubb
Tue Oct 18 14:00:00 2005 Dan Walsh 4.2p1-4
- Change selinux patch to use get_default_context_with_rolelevel in libselinux.
Thu Oct 13 14:00:00 2005 Tomas Mraz 4.2p1-3
- Update selinux patch to use getseuserbyname
Fri Oct 7 14:00:00 2005 Tomas Mraz 4.2p1-2
- use include instead of pam_stack in pam config
- use fork+exec instead of system in scp - CVE-2006-0225 (#168167)
- upstream patch for displaying authentication errors
Tue Sep 6 14:00:00 2005 Tomas Mraz 4.2p1-1
- upgrade to a new upstream version
Tue Aug 16 14:00:00 2005 Tomas Mraz 4.1p1-5
- use x11-ssh-askpass if openssh-askpass-gnome is not installed (#165207)
- install ssh-copy-id from contrib (#88707)
Wed Jul 27 14:00:00 2005 Tomas Mraz 4.1p1-4
- don\'t deadlock on exit with multiple X forwarded channels (#152432)
- don\'t use X11 port which can\'t be bound on all IP families (#163732)
Wed Jun 29 14:00:00 2005 Tomas Mraz 4.1p1-3
- fix small regression caused by the nologin patch (#161956)
- fix race in getpeername error checking (mindrot #1054)
Thu Jun 9 14:00:00 2005 Tomas Mraz 4.1p1-2
- use only pam_nologin for nologin testing
Mon Jun 6 14:00:00 2005 Tomas Mraz 4.1p1-1
- upgrade to a new upstream version
- call pam_loginuid as a pam session module
Mon May 16 14:00:00 2005 Tomas Mraz 4.0p1-3
- link libselinux only to sshd (#157678)
Mon Apr 4 14:00:00 2005 Tomas Mraz 4.0p1-2
- fixed Local/RemoteForward in ssh_config.5 manpage
- fix fatal when Local/RemoteForward is used and scp run (#153258)
- don\'t leak user validity when using krb5 authentication
Thu Mar 24 13:00:00 2005 Tomas Mraz 4.0p1-1
- upgrade to 4.0p1
- remove obsolete groups patch
Wed Mar 16 13:00:00 2005 Elliot Lee
- rebuilt
Mon Feb 28 13:00:00 2005 Nalin Dahyabhai 3.9p1-12
- rebuild so that configure can detect that krb5_init_ets is gone now
Mon Feb 21 13:00:00 2005 Tomas Mraz 3.9p1-11
- don\'t call syslog in signal handler
- allow password authentication when copying from remote
to remote machine (#103364)
Wed Feb 9 13:00:00 2005 Tomas Mraz
- add spaces to messages in initscript (#138508)
Tue Feb 8 13:00:00 2005 Tomas Mraz 3.9p1-10
- enable trusted forwarding by default if X11 forwarding is
required by user (#137685 and duplicates)
- disable protocol 1 support by default in sshd server config (#88329)
- keep the gnome-askpass dialog above others (#69131)
Fri Feb 4 13:00:00 2005 Tomas Mraz
- change permissions on pam.d/sshd to 0644 (#64697)
- patch initscript so it doesn\'t kill opened sessions if
the sshd daemon isn\'t running anymore (#67624)
Mon Jan 3 13:00:00 2005 Bill Nottingham 3.9p1-9
- don\'t use initlog
Mon Nov 29 13:00:00 2004 Thomas Woerner 3.9p1-8.1
- fixed PIE build for all architectures
Mon Oct 4 14:00:00 2004 Nalin Dahyabhai 3.9p1-8
- add a --enable-vendor-patchlevel option which allows a ShowPatchLevel option
to enable display of a vendor patch level during version exchange (#120285)
- configure with --disable-strip to build useful debuginfo subpackages
Mon Sep 20 14:00:00 2004 Bill Nottingham 3.9p1-7
- when using gtk2 for askpass, don\'t buildprereq gnome-libs-devel
Tue Sep 14 14:00:00 2004 Nalin Dahyabhai 3.9p1-6
- build
Mon Sep 13 14:00:00 2004 Nalin Dahyabhai
- disable ACSS support
Thu Sep 2 14:00:00 2004 Daniel Walsh 3.9p1-5
- Change selinux patch to use get_default_context_with_role in libselinux.
Thu Sep 2 14:00:00 2004 Daniel Walsh 3.9p1-4
- Fix patch
* Bad debug statement.
* Handle root/sysadm_r:kerberos
Thu Sep 2 14:00:00 2004 Daniel Walsh 3.9p1-3
- Modify Colin Walter\'s patch to allow specifying rule during connection
Tue Aug 31 14:00:00 2004 Daniel Walsh 3.9p1-2
- Fix TTY handling for SELinux
Tue Aug 24 14:00:00 2004 Daniel Walsh 3.9p1-1
- Update to upstream
Sun Aug 1 14:00:00 2004 Alan Cox 3.8.1p1-5
- Apply buildreq fixup patch (#125296)
Tue Jun 15 14:00:00 2004 Daniel Walsh 3.8.1p1-4
- Clean up patch for upstream submission.
Tue Jun 15 14:00:00 2004 Elliot Lee
- rebuilt
Wed Jun 9 14:00:00 2004 Daniel Walsh 3.8.1p1-2
- Remove use of pam_selinux and patch selinux in directly.
Mon Jun 7 14:00:00 2004 Nalin Dahyabhai 3.8.1p1-1
- request gssapi-with-mic by default but not delegation (flag day for anyone
who used previous gssapi patches)
- no longer request x11 forwarding by default
Thu Jun 3 14:00:00 2004 Daniel Walsh 3.6.1p2-36
- Change pam file to use open and close with pam_selinux
Tue Jun 1 14:00:00 2004 Nalin Dahyabhai 3.8.1p1-0
- update to 3.8.1p1
- add workaround from CVS to reintroduce passwordauth using pam
Tue Jun 1 14:00:00 2004 Daniel Walsh 3.6.1p2-35
- Remove CLOSEXEC on STDERR
Tue Mar 16 13:00:00 2004 Daniel Walsh 3.6.1p2-34
* Wed Mar 03 2004 Phil Knirsch 3.6.1p2-33.30.1
- Built RHLE3 U2 update package.
Wed Mar 3 13:00:00 2004 Daniel Walsh 3.6.1p2-33
- Close file descriptors on exec
Mon Mar 1 13:00:00 2004 Thomas Woerner 3.6.1p2-32
- fixed pie build
Thu Feb 26 13:00:00 2004 Daniel Walsh 3.6.1p2-31
- Add restorecon to startup scripts
Thu Feb 26 13:00:00 2004 Daniel Walsh 3.6.1p2-30
- Add multiple qualified to openssh
Mon Feb 23 13:00:00 2004 Daniel Walsh 3.6.1p2-29
- Eliminate selinux code and use pam_selinux
Fri Feb 13 13:00:00 2004 Elliot Lee
- rebuilt
Mon Jan 26 13:00:00 2004 Daniel Walsh 3.6.1p2-27
- turn off pie on ppc
Mon Jan 26 13:00:00 2004 Daniel Walsh 3.6.1p2-26
- fix is_selinux_enabled
Wed Jan 14 13:00:00 2004 Daniel Walsh 3.6.1p2-25
- Rebuild to grab shared libselinux
Wed Dec 3 13:00:00 2003 Daniel Walsh 3.6.1p2-24
- turn on selinux
Tue Nov 18 13:00:00 2003 Nalin Dahyabhai
- un#ifdef out code for reporting password expiration in non-privsep
mode (#83585)
Mon Nov 10 13:00:00 2003 Nalin Dahyabhai
- add machinery to build with/without -fpie/-pie, default to doing so
Thu Nov 6 13:00:00 2003 David Woodhouse 3.6.1p2-23
- Don\'t whinge about getsockopt failing (#109161)
Fri Oct 24 14:00:00 2003 Nalin Dahyabhai
- add missing buildprereq on zlib-devel (#104558)
Mon Oct 13 14:00:00 2003 Daniel Walsh 3.6.1p2-22
- turn selinux off
Mon Oct 13 14:00:00 2003 Daniel Walsh 3.6.1p2-21.sel
- turn selinux on
Fri Sep 19 14:00:00 2003 Daniel Walsh 3.6.1p2-21
- turn selinux off
Fri Sep 19 14:00:00 2003 Daniel Walsh 3.6.1p2-20.sel
- turn selinux on
Fri Sep 19 14:00:00 2003 Nalin Dahyabhai
- additional fix for apparently-never-happens double-free in buffer_free()
- extend fix for #103998 to cover SSH1
Wed Sep 17 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-19
- rebuild
Wed Sep 17 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-18
- additional buffer manipulation cleanups from Solar Designer
Wed Sep 17 14:00:00 2003 Daniel Walsh 3.6.1p2-17
- turn selinux off
Wed Sep 17 14:00:00 2003 Daniel Walsh 3.6.1p2-16.sel
- turn selinux on
Tue Sep 16 14:00:00 2003 Bill Nottingham 3.6.1p2-15
- rebuild
Tue Sep 16 14:00:00 2003 Bill Nottingham 3.6.1p2-14
- additional buffer manipulation fixes (CAN-2003-0695)
Tue Sep 16 14:00:00 2003 Daniel Walsh 3.6.1p2-13.sel
- turn selinux on
Tue Sep 16 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-12
- rebuild
Tue Sep 16 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-11
- apply patch to store the correct buffer size in allocated buffers
(CAN-2003-0693)
- skip the initial PAM authentication attempt with an empty password if
empty passwords are not permitted in our configuration (#103998)
Fri Sep 5 14:00:00 2003 Daniel Walsh 3.6.1p2-10
- turn selinux off
Fri Sep 5 14:00:00 2003 Daniel Walsh 3.6.1p2-9.sel
- turn selinux on
Tue Aug 26 14:00:00 2003 Daniel Walsh 3.6.1p2-8
- Add BuildPreReq gtk2-devel if gtk2
Tue Aug 12 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-7
- rebuild
Tue Aug 12 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-6
- modify patch which clears the supplemental group list at startup to only
complain if setgroups() fails if sshd has euid == 0
- handle krb5 installed in %{_prefix} or elsewhere by using krb5-config
Mon Jul 28 14:00:00 2003 Daniel Walsh 3.6.1p2-5
- Add SELinux patch
Tue Jul 22 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-4
- rebuild
Mon Jun 16 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-3
- rebuild
Mon Jun 16 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-2
- rebuild
Thu Jun 5 14:00:00 2003 Nalin Dahyabhai 3.6.1p2-1
- update to 3.6.1p2
Wed Jun 4 14:00:00 2003 Elliot Lee
6 rebuilt
Mon Mar 24 13:00:00 2003 Florian La Roche
- add patch for getsockopt() call to work on bigendian 64bit archs
Fri Feb 14 13:00:00 2003 Nalin Dahyabhai 3.5p1-6
- move scp to the -clients subpackage, because it directly depends on ssh
which is also in -clients (#84329)
Mon Feb 10 13:00:00 2003 Nalin Dahyabhai 3.5p1-5
- rebuild
Wed Jan 22 13:00:00 2003 Tim Powers
- rebuilt
Tue Jan 7 13:00:00 2003 Nalin Dahyabhai 3.5p1-3
- rebuild
Tue Nov 12 13:00:00 2002 Nalin Dahyabhai 3.5p1-2
- patch PAM configuration to use relative path names for the modules, allowing
us to not worry about which arch the modules are built for on multilib systems
Tue Oct 15 14:00:00 2002 Nalin Dahyabhai 3.5p1-1
- update to 3.5p1, merging in filelist/perm changes from the upstream spec
Fri Oct 4 14:00:00 2002 Nalin Dahyabhai 3.4p1-3
- merge
Thu Sep 12 14:00:00 2002 Than Ngo 3.4p1-2.1
- fix to build on multilib systems
Thu Aug 29 14:00:00 2002 Curtis Zinzilieta 3.4p1-2gss
- added gssapi patches and uncommented patch here
Wed Aug 14 14:00:00 2002 Nalin Dahyabhai 3.4p1-2
- pull patch from CVS to fix too-early free in ssh-keysign (#70009)
Thu Jun 27 14:00:00 2002 Nalin Dahyabhai 3.4p1-1
- 3.4p1
- drop anon mmap patch
Tue Jun 25 14:00:00 2002 Nalin Dahyabhai 3.3p1-2
- rework the close-on-exit docs
- include configuration file man pages
- make use of nologin as the privsep shell optional
Mon Jun 24 14:00:00 2002 Nalin Dahyabhai 3.3p1-1
- update to 3.3p1
- merge in spec file changes from upstream (remove setuid from ssh, ssh-keysign)
- disable gtk2 askpass
- require pam-devel by filename rather than by package for erratum
- include patch from Solar Designer to work around anonymous mmap failures
Fri Jun 21 14:00:00 2002 Tim Powers
- automated rebuild
Fri Jun 7 14:00:00 2002 Nalin Dahyabhai 3.2.3p1-3
- don\'t require autoconf any more
Fri May 31 14:00:00 2002 Nalin Dahyabhai 3.2.3p1-2
- build gnome-ssh-askpass with gtk2
Tue May 28 14:00:00 2002 Nalin Dahyabhai 3.2.3p1-1
- update to 3.2.3p1
- merge in spec file changes from upstream
Fri May 17 14:00:00 2002 Nalin Dahyabhai 3.2.2p1-1
- update to 3.2.2p1
Fri May 17 14:00:00 2002 Nalin Dahyabhai 3.1p1-4
- drop buildreq on db1-devel
- require pam-devel by package name
- require autoconf instead of autoconf253 again
Tue Apr 2 14:00:00 2002 Nalin Dahyabhai 3.1p1-3
- pull patch from CVS to avoid printing error messages when some of the
default keys aren\'t available when running ssh-add
- refresh to current revisions of Simon\'s patches
Thu Mar 21 13:00:00 2002 Nalin Dahyabhai 3.1p1-2gss
- reintroduce Simon\'s gssapi patches
- add buildprereq for autoconf253, which is needed to regenerate configure
after applying the gssapi patches
- refresh to the latest version of Markus\'s patch to build properly with
older versions of OpenSSL
Thu Mar 7 13:00:00 2002 Nalin Dahyabhai 3.1p1-2
- bump and grind (through the build system)
Thu Mar 7 13:00:00 2002 Nalin Dahyabhai 3.1p1-1
- require sharutils for building (mindrot #137)
- require db1-devel only when building for 6.x (#55105), which probably won\'t
work anyway (3.1 requires OpenSSL 0.9.6 to build), but what the heck
- require pam-devel by file (not by package name) again
- add Markus\'s patch to compile with OpenSSL 0.9.5a (from
http://bugzilla.mindrot.org/show_bug.cgi?id=141) and apply it if we\'re
building for 6.x
Thu Mar 7 13:00:00 2002 Nalin Dahyabhai 3.1p1-0
- update to 3.1p1
Tue Mar 5 13:00:00 2002 Nalin Dahyabhai SNAP-20020305
- update to SNAP-20020305
- drop debug patch, fixed upstream
Wed Feb 20 13:00:00 2002 Nalin Dahyabhai SNAP-20020220
- update to SNAP-20020220 for testing purposes (you\'ve been warned, if there\'s
anything to be warned about, gss patches won\'t apply, I don\'t mind)
Wed Feb 13 13:00:00 2002 Nalin Dahyabhai 3.0.2p1-3
- add patches from Simon Wilkinson and Nicolas Williams for GSSAPI key
exchange, authentication, and named key support
Wed Jan 23 13:00:00 2002 Nalin Dahyabhai 3.0.2p1-2
- remove dependency on db1-devel, which has just been swallowed up whole
by gnome-libs-devel
Sat Dec 29 13:00:00 2001 Nalin Dahyabhai
- adjust build dependencies so that build6x actually works right (fix
from Hugo van der Kooij)
Tue Dec 4 13:00:00 2001 Nalin Dahyabhai 3.0.2p1-1
- update to 3.0.2p1
Fri Nov 16 13:00:00 2001 Nalin Dahyabhai 3.0.1p1-1
- update to 3.0.1p1
Tue Nov 13 13:00:00 2001 Nalin Dahyabhai
- update to current CVS (not for use in distribution)
Thu Nov 8 13:00:00 2001 Nalin Dahyabhai 3.0p1-1
- merge some of Damien Miller changes from the upstream
3.0p1 spec file and init script
Wed Nov 7 13:00:00 2001 Nalin Dahyabhai
- update to 3.0p1
- update to x11-ssh-askpass 1.2.4.1
- change build dependency on a file from pam-devel to the pam-devel package
- replace primes with moduli
Thu Sep 27 14:00:00 2001 Nalin Dahyabhai 2.9p2-9
- incorporate fix from Markus Friedl\'s advisory for IP-based authorization bugs
Thu Sep 13 14:00:00 2001 Bernhard Rosenkraenzer 2.9p2-8